Skip to content

Migrate attestation_service proto codegen to buf so we can use protovalidate UUID constraints in shared types #27

Description

@atulpatildbz

Background

In PR #8 (comment thread) we wanted to add (buf.validate.field).string.uuid = true to KeyHandle.handle so the gRPC layer would reject malformed UUIDs declaratively, instead of duplicating uuid.Parse(...) checks in every handler.

This had to be reverted because km_common/proto/crypto_types.proto (which defines KeyHandle) is imported by keymanager/attestation_service/proto/api.proto, and attestation's codegen uses protoc (because it depends on attestation.proto from confidential-space which is not a buf module). buf.validate annotations require buf codegen.

Possible solution

Migrate attestation_service's codegen to buf, then re-add the UUID constraint to KeyHandle.handle and remove the manual uuid.Parse calls from:

  • key_protection_service/grpc_server.go (DecapAndSeal, DestroyKEMKey, GetKEMKey)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions